How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we...

33
. Bruce Snell Cybersecurity and Privacy Director, Intel Security How IoT is Redefining Data Privacy, Safety, Governance and Trust

Transcript of How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we...

Page 1: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Bruce SnellCybersecurity and Privacy Director, Intel Security

How IoT is Redefining Data Privacy, Safety, Governance and Trust

Page 2: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

2

Total Malware

10%

Page 3: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

New Mobile Malware

Malware numbers spawned by increased Android updates 72%

Page 4: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

4

Total Mac OS Malware

Mac OS under attack

Page 5: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

New Ransomware

Open-source ransomware code and dark web ransomware-as-a-service making attacks simpler 26%

Page 6: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

6

155%(over last year)

Total Ransomware

Page 7: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

There are 327 new threats every minute

More than 5 every second

Page 8: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

2B3B

More users2 billion in 20103 billion in 20154 billion in 2019

5B 16.3B

More connected devices5 billion in 201016.3 billion in 2015200 billion in 2020!

4B 200B

Page 9: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Attack surfaceS

Page 10: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Page 11: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Police Drones

Paris Police design brief• Crowd-Monitoring• 10m/s (22mph)• 1km range• HD & thermal cameras• 30 min flight time• 1kg payload• Autonomous and manual flight

Page 12: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

The Climb and Crash of UK PD

2009

Quadcopter obtained ($19k), officers trained

2010

Crashed in river

2011

Make first arrest

October

February

Grounded by Civil Aviation Authority 1 week later

October

Operation ceased

Page 13: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Global Aerial Drone Market

Bil

lio

ns

Defense

Civilian

Source: Teal Group, BI Intelligence Estimates, Michael Toscano

2015-2020 growth (CAGR)

Page 14: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

“While we project more than 100,000 new jobs by 2025, states that create favorable regulatoryand business environments for the industry and the technology will likely siphon jobs away from states that do not.”

Source: Association for Unmanned Vehicle Systems International: The Economic Impact of Unmaned Aircraft Systems Integration in the US

Page 15: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Economic Impact

Taxes

Jobs Created

$2.7B

$28M

3,363

Source: Association for Unmanned Vehicle Systems International: The Economic Impact of Unmaned Aircraft Systems Integration in the US

Page 16: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Page 17: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Page 18: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Page 19: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Page 20: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Passive Keyless Entry

Remote Key

TPMS

ADAS SystemECU

Lighting SystemECU (interior and exterior)

Engine and Transmission

ECU

Steering and Braking ECU

Vehicle AccessSystem ECU

Remote Link App

Airbag ECU

Bluetooth

USB

DSRB-BasedReceiver (V2X)OBD II

Page 21: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Page 22: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

• Operating system kernel• Networking software/WiFi• User interface• Memory• Local files and storage system• Access control/security software

• Cloud VM and Control Apps• Web App• Memory• Local files and storage system• Access control/security software

Page 23: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

HACKERS Want your patterns

Page 24: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Page 25: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Page 26: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

BlackEnergy 3

Multiple attacks against Ukrainian targets

• Developed in 2007

• Power grid taken down 12/23/15

• Kiev airport hit 1/18/16

Attacking operator stations

Infections via social engineering

Plugins:

Page 27: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

Where do we start?

Page 28: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

28

63% of data breaches involved a weak password

Page 29: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

29

30% of phishing emails are opened

225 Seconds

13% of those click through

Page 30: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

30

85% of successful exploits were top 10 vulnerabilities

Page 31: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

31

Training and Awareness are key

Page 32: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

In summary

5 new threats every second

Increase in users and devices

IoT under attack as we speak

Security is key for future growth

Fee free to follow up with questions via twitter: @brucesnell

Page 33: How IoT is Redefining Data Privacy, Safety, Governance and Trust · 2016-08-09 · “While we project more than 100,000 new jobs by 2025, states that create favorable regulatory

.

33